Send us feedback
No associated aliases
detects and removes this threat.
This threat can download malicious code onto your PC.
We have seen it installed at the same time as unwanted software that we detect as SoftwareBundler:Win32/InstalleRex.
Use the following free Microsoft software to detect and remove this threat:
You should also run a full scan. A full scan might find hidden malware.
You can also visit our advanced troubleshooting page or search the Microsoft virus and malware community for more help.
If you’re using Windows XP, see our Windows XP end of support page.
This threat is written in Python and uses multiple layers of obfuscation.
We have seen it installed to %ProgramFiles% using the file name format <adjective> <noun>\<adjective> <noun>.exe, for example:
It can also be registered as a service under the following system registry key:
Connects to a remote host
We have seen this threat connect to the following web domains to download and run malicious code:
Analysis by Jireh Sanico
Take these steps to help prevent infection on your PC.
The following can indicate that you have this threat on your PC: